Skip to content

Add wolfBoot target for Infineon PSOC Control C3 - #915

Open
dgarske wants to merge 2 commits into
wolfSSL:masterfrom
dgarske:psoc_c3
Open

dgarske wants to merge 2 commits into
wolfSSL:masterfrom
dgarske:psoc_c3

Conversation

@dgarske

@dgarske dgarske commented Sep 29, 2026

Copy link
Copy Markdown
Member

The PSOC Control C3 family (PSC3, CAT1B) is an Arm Cortex-M33 motor-control MCU. wolfBoot runs as the first application the BootROM launches, verifies the signed firmware and boots it. The port is bare metal: no Peripheral Driver Library, no BSP and no generated configuration, so it builds with an arm-none-eabi toolchain alone.

What it adds

  • hal/psoc_c3.{c,h,ld} - HAL, register definitions and linker script
  • hal/spi/spi_drv_psoc_c3.{c,h}, hal/i2c/i2c_drv_psoc_c3.{c,h} - SCB serial back-ends
  • include/i2c_drv.h - a generic I2C master interface, which wolfBoot did not previously have
  • config/examples/psoc_c3.config with -128k, -tpm (SPI) and -tpm-i2c variants, and a CI job for each
  • arch.mk target block, test-app/app_psoc_c3.c and its linker script, and a host unit test for the clock divider

Touches shared code

  • src/tpm.c - adds a TIS-over-I2C transport beside the existing SPI one, selected by WOLFBOOT_TPM_I2C and documented in docs/TPM.md. Also corrects the advanced-IO callback signature, which declared int where TPM2HalIoCb uses INT32, so the callback could not be assigned to wolfTPM2_Init().
  • include/spi_drv.h - target arm for the new back-end, and widens the spi_cs_on/spi_cs_off/spi_write/spi_read prototype guard to cover TPM-only builds, where those functions are defined but were not declared.
  • options.mk - selects the I2C back-end when WOLFBOOT_TPM_I2C is set.

Three properties of this family shape the port:

  • Flash is programmed through a BootROM function-pointer table rather than a flash controller register block.
  • Erased flash reads as 0x00, not 0xFF, so the configs set FLAGS_INVERT=1 and NVM_FLASH_WRITEONCE=0. Without the inverted polarity the state written by wolfBoot_update_trigger() cannot be told apart from erased flash and no update is taken.
  • Every memory appears through four aliases crossing Secure/Non-secure with the code and system buses, and a pin must be claimed as secure through HSIOM_SECURE_PRT before its HSIOM and GPIO registers accept a write at all.

Hardware / test status

Validated end to end on a PSOC Control C3 evaluation kit fitted with a C3M6 (on-board SEGGER J-Link, console 115200 8N1): console output, image integrity and ECC256 signature verification, the handoff to the application, and a full A/B update in which the application triggers an update, wolfBoot swaps the partitions through the swap sector, and the new version confirms success.

The 128 KB layout and the other family members are build-tested only; flash size is the only geometry that differs across the family.

@dgarske dgarske self-assigned this Sep 29, 2026
Copilot AI balanced review requested due to automatic review settings September 29, 2026 16:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

Review effort: Lite
Findings: 1 High severity · 2 Medium severity · 2 Low severity

Open (5)
What changed in this PR

Adds a new bare-metal wolfBoot target for Infineon PSOC Control C3, including HAL/linker support, serial back-ends (SPI/I2C), and TPM-over-I2C support.

Changes:

  • Added PSOC C3 HAL (register defs, flash via BootROM table, pin/peripheral clock setup) plus linker scripts and test application support.
  • Added SPI and I2C SCB drivers, a generic i2c_drv.h interface, and TPM TIS-over-I2C transport option (WOLFBOOT_TPM_I2C).
  • Added docs, CI build jobs, and a host unit test for the fractional divider math.
File Description
tools/​unit-tests/​unit-psoc-c3-divider.c Adds a host unit test for PSOC C3 16.5 divider math.
tools/​unit-tests/​Makefile Registers and builds the new PSOC C3 divider unit test.
test-app/​app_psoc_c3.c Adds a bare-metal PSOC C3 test app exercising A/B update flow.
test-app/​Makefile Adds psoc_c3 target settings (CPU flags, linker script selection).
test-app/​ARM-psoc_c3.ld Adds a PSOC C3 test application linker script template.
src/​tpm.c Adds TPM TIS-over-I2C transport + fixes advanced IO callback signature types.
options.mk Wires WOLFBOOT_TPM_I2C build option to select the I2C backend and ADV_IO.
include/​spi_drv.h Adds PSOC C3 SPI backend include + declares SPI helpers for TPM-only builds.
include/​i2c_drv.h Introduces a generic I2C master driver interface for TPM-over-I2C.
hal/​spi/​spi_drv_psoc_c3.h Defines PSOC C3 SPI pinout/clocking configuration defaults.
hal/​spi/​spi_drv_psoc_c3.c Implements PSOC C3 SPI driver with bounded FIFO waits and TPM xfer support.
hal/​psoc_c3.ld Adds PSOC C3 wolfBoot linker script (flash/RAM regions, sections).
hal/​psoc_c3.h Adds PSOC C3 register definitions and divider computation helper.
hal/​psoc_c3.c Implements PSOC C3 HAL (flash ops via BootROM, clocks, pins, UART, boot prep).
hal/​i2c/​i2c_drv_sim.c Adds simulator stub I2C backend for build-testing TPM-over-I2C path.
hal/​i2c/​i2c_drv_psoc_c3.h Defines PSOC C3 I2C pinout/clocking configuration defaults.
hal/​i2c/​i2c_drv_psoc_c3.c Implements PSOC C3 I2C master driver (polled, bounded waits).
docs/​Targets.md Documents PSOC Control C3 port, memory aliases, flash behavior, build/flash steps.
docs/​TPM.md Documents WOLFBOOT_TPM_I2C option and its build implications.
config/​examples/​psoc_c3.config Adds example config for PSOC C3 including erased-flash behavior settings.
arch.mk Adds psoc_c3 target block, wiring defaults, and I2C target selection.
Makefile Extends clean/cppcheck to cover new hal/i2c sources/objects.
.gitignore Ignores the new unit test binary artifact.
.github/​workflows/​test-configs.yml Adds CI build jobs for PSOC C3 configs and TPM SPI/I2C variants.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread hal/i2c/i2c_drv_psoc_c3.c Outdated
Comment thread hal/psoc_c3.c
Comment thread hal/psoc_c3.h Outdated
Comment thread hal/psoc_c3.ld
Comment thread test-app/app_psoc_c3.c

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment on lines +12 to +13
#include "../../hal/psoc_c3.h"

Comment thread hal/psoc_c3.h
Comment on lines +23 to +24
#ifndef _PSOC_C3_H_
#define _PSOC_C3_H_
Comment thread hal/psoc_c3.ld
Comment on lines +19 to +23
.edidx :
{
. = ALIGN(4);
*(.ARM.exidx*)
} > FLASH
Comment on lines +29 to +30
printf("FAIL %s: pclk=%u target=%u -> int=%u frac=%u, expected %u/%u\n",
what, pclk, target, i, f, exp_i, exp_f);
Comment on lines +34 to +35
printf("ok %s: int=%u frac=%u -> %u Hz\n", what, i, f,
produced(pclk, i, f));
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants